[v6.1] WARNING in pkcs1pad_verify

0 views
Skip to first unread message

syzbot

unread,
Aug 16, 2026, 4:35:42 PM (11 hours ago) Aug 16
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: e4f7d8be268e Linux 6.1.182
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=160b9949580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=5bde7e801f46da43adc6
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/7cd9b1875376/disk-e4f7d8be.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/4b5d35d18c31/vmlinux-e4f7d8be.xz
kernel image: https://storage.googleapis.com/syzbot-assets/d5ee64c2af77/Image-e4f7d8be.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5bde7e...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 4934 at crypto/rsa-pkcs1pad.c:540 pkcs1pad_verify+0x454/0x5ac crypto/rsa-pkcs1pad.c:540
Modules linked in:
CPU: 1 PID: 4934 Comm: syz.0.204 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : pkcs1pad_verify+0x454/0x5ac crypto/rsa-pkcs1pad.c:540
lr : pkcs1pad_verify+0x454/0x5ac crypto/rsa-pkcs1pad.c:540
sp : ffff8000216e7630
x29: ffff8000216e7640 x28: ffff0000f54a3000 x27: ffff0000d0d15600
x26: ffff0000d0d15600 x25: ffff8000216e77c0 x24: dfff800000000000
x23: ffff8000216e79a0 x22: 0000000000000000 x21: ffff0000f54a3038
x20: 0000000000000200 x19: ffff0000f54a3000 x18: 1fffe00033e7697e
x17: ffff80000a76afc4 x16: ffff800011b90080 x15: 8a8992b545d160b9
x14: 0000000000000002 x13: 1ffff000042dceed x12: 0000000000080000
x11: 000000000000545e x10: ffff8000219ea000 x9 : ffff80000a6632a8
x8 : 000000000000545f x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000000
x2 : 0000000000000008 x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
pkcs1pad_verify+0x454/0x5ac crypto/rsa-pkcs1pad.c:540
crypto_akcipher_verify include/crypto/akcipher.h:370 [inline]
public_key_verify_signature+0x720/0xb30 crypto/asymmetric_keys/public_key.c:460
public_key_verify_signature_2+0x48/0x58 crypto/asymmetric_keys/public_key.c:479
verify_signature+0xe8/0x108 crypto/asymmetric_keys/signature.c:154
asymmetric_key_verify_signature+0x154/0x1ec crypto/asymmetric_keys/asymmetric_type.c:614
keyctl_pkey_verify+0x1c4/0x248 security/keys/keyctl_pkey.c:326
__do_sys_keyctl security/keys/keyctl.c:2017 [inline]
__se_sys_keyctl security/keys/keyctl.c:1886 [inline]
__arm64_sys_keyctl+0x62c/0x8e0 security/keys/keyctl.c:1886
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x290 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x13c/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x5c/0x134 arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x128 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 1084
hardirqs last enabled at (1083): [<ffff800011c77b24>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:151 [inline]
hardirqs last enabled at (1083): [<ffff800011c77b24>] _raw_spin_unlock_irqrestore+0x48/0xac kernel/locking/spinlock.c:194
hardirqs last disabled at (1084): [<ffff800011b8c2bc>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (914): [<ffff800008031254>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (912): [<ffff800008031220>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup

syzbot

unread,
Aug 16, 2026, 4:46:24 PM (11 hours ago) Aug 16
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: aabd761612db Linux 5.15.215
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=116b9949580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=0056eb6fc8ce1bbc9c82
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/f636f56d3662/disk-aabd7616.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f1a46620f40c/vmlinux-aabd7616.xz
kernel image: https://storage.googleapis.com/syzbot-assets/9b78bb48b022/bzImage-aabd7616.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0056eb...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 4326 at crypto/rsa-pkcs1pad.c:538 pkcs1pad_verify+0x4f8/0x680 crypto/rsa-pkcs1pad.c:538
Modules linked in:
CPU: 1 PID: 4326 Comm: syz.1.22 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:pkcs1pad_verify+0x4f8/0x680 crypto/rsa-pkcs1pad.c:538
Code: 89 df 89 ee 48 83 c4 28 5b 41 5c 41 5d 41 5e 41 5f 5d e9 eb 0d 00 00 e8 a6 71 c2 fd 0f 0b b8 ea ff ff ff eb c6 e8 98 71 c2 fd <0f> 0b b8 ea ff ff ff eb b8 44 89 f1 80 e1 07 80 c1 03 38 c1 0f 8c
RSP: 0018:ffffc90004c6f7c0 EFLAGS: 00010283
RAX: ffffffff83b68b18 RBX: ffff88802136be00 RCX: 0000000000080000
RDX: ffffc90003dd3000 RSI: 000000000000129d RDI: 000000000000129e
RBP: 0000000000000000 R08: ffffc90004c6f917 R09: ffffc90004c6f908
R10: dffffc0000000000 R11: fffff5200098df23 R12: ffff88801f00bc00
R13: dffffc0000000000 R14: ffff88802136be44 R15: dffffc0000000000
FS: 00007f4d037c36c0(0000) GS:ffff8880b9100000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fd401d382f8 CR3: 00000000735d5000 CR4: 00000000003506e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
crypto_akcipher_verify include/crypto/akcipher.h:370 [inline]
public_key_verify_signature+0x87f/0xd40 crypto/asymmetric_keys/public_key.c:460
asymmetric_key_verify_signature+0x171/0x210 crypto/asymmetric_keys/asymmetric_type.c:582
keyctl_pkey_verify+0x40e/0x430 security/keys/keyctl_pkey.c:326
__do_sys_keyctl security/keys/keyctl.c:2017 [inline]
__se_sys_keyctl+0x684/0xa20 security/keys/keyctl.c:1886
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f4d0556b0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f4d037c3028 EFLAGS: 00000246 ORIG_RAX: 00000000000000fa
RAX: ffffffffffffffda RBX: 00007f4d057f2fa0 RCX: 00007f4d0556b0d9
RDX: 0000200000000040 RSI: 0000200000000000 RDI: 000000000000001c
RBP: 00007f4d05602024 R08: 0000200000000440 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f4d057f3038 R14: 00007f4d057f2fa0 R15: 00007ffd21aa1728
</TASK>

syzbot

unread,
Aug 16, 2026, 4:57:34 PM (11 hours ago) Aug 16
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: e4f7d8be268e Linux 6.1.182
git tree: linux-6.1.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1032c679580000
kernel config: https://syzkaller.appspot.com/x/.config?x=872c04466179833f
dashboard link: https://syzkaller.appspot.com/bug?extid=5bde7e801f46da43adc6
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
userspace arch: arm64
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=136056c6580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=16457a79580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/7cd9b1875376/disk-e4f7d8be.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/4b5d35d18c31/vmlinux-e4f7d8be.xz
kernel image: https://storage.googleapis.com/syzbot-assets/d5ee64c2af77/Image-e4f7d8be.gz.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+5bde7e...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 0 PID: 4465 at crypto/rsa-pkcs1pad.c:540 pkcs1pad_verify+0x454/0x5ac crypto/rsa-pkcs1pad.c:540
Modules linked in:
CPU: 0 PID: 4465 Comm: syz.0.17 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/07/2026
pstate: 82400005 (Nzcv daif +PAN -UAO +TCO -DIT -SSBS BTYPE=--)
pc : pkcs1pad_verify+0x454/0x5ac crypto/rsa-pkcs1pad.c:540
lr : pkcs1pad_verify+0x454/0x5ac crypto/rsa-pkcs1pad.c:540
sp : ffff8000208a7630
x29: ffff8000208a7640 x28: ffff0000cb023000 x27: ffff0000d49e1600
x26: ffff0000d49e1600 x25: ffff8000208a77c0 x24: dfff800000000000
x23: ffff8000208a79a0 x22: 0000000000000000 x21: ffff0000cb023038
x20: 0000000000000200 x19: ffff0000cb023000 x18: 1fffe00033e7277e
x17: ffff80000a76afc4 x16: ffff800011b90080 x15: 8a8992b545d160b9
x14: 0000000000000002 x13: 1ffff00004114eed x12: 0000000000000000
x11: ff0080000a6632a8 x10: 0000000000000000 x9 : ffff80000a6632a8
x8 : ffff0000d0d75400 x7 : 0000000000000000 x6 : 0000000000000000
x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000000
x2 : 0000000000000008 x1 : 0000000000000000 x0 : 0000000000000000
Call trace:
pkcs1pad_verify+0x454/0x5ac crypto/rsa-pkcs1pad.c:540
crypto_akcipher_verify include/crypto/akcipher.h:370 [inline]
public_key_verify_signature+0x720/0xb30 crypto/asymmetric_keys/public_key.c:460
public_key_verify_signature_2+0x48/0x58 crypto/asymmetric_keys/public_key.c:479
verify_signature+0xe8/0x108 crypto/asymmetric_keys/signature.c:154
asymmetric_key_verify_signature+0x154/0x1ec crypto/asymmetric_keys/asymmetric_type.c:614
keyctl_pkey_verify+0x1c4/0x248 security/keys/keyctl_pkey.c:326
__do_sys_keyctl security/keys/keyctl.c:2017 [inline]
__se_sys_keyctl security/keys/keyctl.c:1886 [inline]
__arm64_sys_keyctl+0x62c/0x8e0 security/keys/keyctl.c:1886
__invoke_syscall arch/arm64/kernel/syscall.c:38 [inline]
invoke_syscall+0x98/0x290 arch/arm64/kernel/syscall.c:52
el0_svc_common+0x13c/0x258 arch/arm64/kernel/syscall.c:140
do_el0_svc+0x5c/0x134 arch/arm64/kernel/syscall.c:204
el0_svc+0x58/0x128 arch/arm64/kernel/entry-common.c:637
el0t_64_sync_handler+0x84/0xf0 arch/arm64/kernel/entry-common.c:655
el0t_64_sync+0x18c/0x190 arch/arm64/kernel/entry.S:585
irq event stamp: 1712
hardirqs last enabled at (1711): [<ffff800011c77b24>] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:151 [inline]
hardirqs last enabled at (1711): [<ffff800011c77b24>] _raw_spin_unlock_irqrestore+0x48/0xac kernel/locking/spinlock.c:194
hardirqs last disabled at (1712): [<ffff800011b8c2bc>] el1_dbg+0x24/0x80 arch/arm64/kernel/entry-common.c:405
softirqs last enabled at (1570): [<ffff800008031254>] local_bh_enable+0x10/0x34 include/linux/bottom_half.h:32
softirqs last disabled at (1568): [<ffff800008031220>] local_bh_disable+0x10/0x34 include/linux/bottom_half.h:19
---[ end trace 0000000000000000 ]---


---
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.

syzbot

unread,
Aug 16, 2026, 5:25:32 PM (10 hours ago) Aug 16
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: aabd761612db Linux 5.15.215
git tree: linux-5.15.y
console output: https://syzkaller.appspot.com/x/log.txt?x=122b5a79580000
kernel config: https://syzkaller.appspot.com/x/.config?x=f161cbc9aef65db0
dashboard link: https://syzkaller.appspot.com/bug?extid=0056eb6fc8ce1bbc9c82
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=11d36a25580000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=11c856c6580000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/f636f56d3662/disk-aabd7616.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/f1a46620f40c/vmlinux-aabd7616.xz
kernel image: https://storage.googleapis.com/syzbot-assets/9b78bb48b022/bzImage-aabd7616.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0056eb...@syzkaller.appspotmail.com

------------[ cut here ]------------
WARNING: CPU: 1 PID: 4307 at crypto/rsa-pkcs1pad.c:538 pkcs1pad_verify+0x4f8/0x680 crypto/rsa-pkcs1pad.c:538
Modules linked in:
CPU: 1 PID: 4307 Comm: syz.0.17 Not tainted syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
RIP: 0010:pkcs1pad_verify+0x4f8/0x680 crypto/rsa-pkcs1pad.c:538
Code: 89 df 89 ee 48 83 c4 28 5b 41 5c 41 5d 41 5e 41 5f 5d e9 eb 0d 00 00 e8 a6 71 c2 fd 0f 0b b8 ea ff ff ff eb c6 e8 98 71 c2 fd <0f> 0b b8 ea ff ff ff eb b8 44 89 f1 80 e1 07 80 c1 03 38 c1 0f 8c
RSP: 0018:ffffc90002f6f7c0 EFLAGS: 00010293
RAX: ffffffff83b68b18 RBX: ffff88807f531c00 RCX: ffff888029403b80
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: ffffc90002f6f917 R09: ffffc90002f6f908
R10: dffffc0000000000 R11: fffff520005edf23 R12: ffff88802a301800
R13: dffffc0000000000 R14: ffff88807f531c44 R15: dffffc0000000000
FS: 000055558dde2500(0000) GS:ffff8880b9000000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005603e8eb6d80 CR3: 0000000073677000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
<TASK>
crypto_akcipher_verify include/crypto/akcipher.h:370 [inline]
public_key_verify_signature+0x87f/0xd40 crypto/asymmetric_keys/public_key.c:460
asymmetric_key_verify_signature+0x171/0x210 crypto/asymmetric_keys/asymmetric_type.c:582
keyctl_pkey_verify+0x40e/0x430 security/keys/keyctl_pkey.c:326
__do_sys_keyctl security/keys/keyctl.c:2017 [inline]
__se_sys_keyctl+0x684/0xa20 security/keys/keyctl.c:1886
do_syscall_x64 arch/x86/entry/common.c:50 [inline]
do_syscall_64+0x4c/0xa0 arch/x86/entry/common.c:80
entry_SYSCALL_64_after_hwframe+0x66/0xd0
RIP: 0033:0x7f1ab3d9d0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffdc17d6a28 EFLAGS: 00000246 ORIG_RAX: 00000000000000fa
RAX: ffffffffffffffda RBX: 00007f1ab4024fa0 RCX: 00007f1ab3d9d0d9
RDX: 0000200000000040 RSI: 0000200000000000 RDI: 000000000000001c
RBP: 00007f1ab3e34024 R08: 0000200000000440 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f1ab4024fac R14: 00007f1ab4024fa0 R15: 00007f1ab4024fa0
</TASK>
Reply all
Reply to author
Forward
0 new messages